Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format st
Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a fo
A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the f
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident
An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier.
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when script
In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowi
A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attack
An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of use
A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-contr
A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-control
A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled
A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypasse
The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains an uncontrolled format string vulnerabil
An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of th
Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. This vulnerabil
A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer
A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can pla
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format s
A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one
A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 throug
Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address informati
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system ver
Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successfu
A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By cr
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r
n8n is an open source workflow automation platform. From 1.36.0 to before 2.2.0, the Webhook node’s IP whitelist validat
IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 IBM PowerVM could allow a
A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.
A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corrupti
Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers
Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server
A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a mino
HackerOne community member Faraz Ahmed (PakCyberbot) has reported a format string injection in the Revive Adserver setti
An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled
An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper han
A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPor
Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the f
Frequently Asked Questions
What is CWE-134?
CWE-134 (CWE-134) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-134?
There are 42 CVE records associated with CWE-134 in our database. Of these, 3 are critical severity, 18 are high severity, and 13 are medium severity.
How can I protect against CWE-134 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-134 using AI-powered security agents.
Detect CWE-134 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-134 vulnerabilities across your infrastructure.
Get Started